Senior Consultant - Tech Consulting - Cybersecurity - GRC - Cairo
EY
- Location
- Cairo, EG
- Work model
- On-Site
- Level
- Senior
Skills
About this role
As part of our Cyber Technology Consulting practice, you will support the delivery of cybersecurity governance, technology risk and regulatory compliance programs for leading organizations across the Middle East. You will work closely with other senior consultants, managers and client stakeholders to identify regulatory obligations, perform compliance assessments and support governance initiatives. The opportunity We’re looking for consultant/ senior consultant/ assistant manager with strong consulting background and hands-on expertise in implementing enterprise cyber risk and governance programs. This is an exceptional opportunity to work with senior leadership across industries and influence strategic cybersecurity decision-making at the highest levels. Your key responsibilities
Deliver cybersecurity and technology risk consulting engagements across various industries. Conduct cybersecurity and technology risk assessments covering applications, infrastructure, cloud environments, and business processes. Ability to develop risks, controls, compliance requirements and implementation guidance Ability to review regulatory circulars, notices, standards and guidelines and identify applicable technology and cybersecurity obligations Perform cybersecurity governance, compliance, maturity, and control effectiveness assessments against industry standards and regulatory requirements. Assess and enhance governance structures, risk management frameworks, and cybersecurity operating models. Develop and review cybersecurity policies, standards, procedures, and supporting governance documentation. Support clients in establishing and improving compliance monitoring, risk management, and assurance programs. Conduct gap assessments and develop remediation roadmaps aligned with leading frameworks and regulations. Support resilience initiatives including business continuity, disaster recovery, and operational resilience assessments. Identify risks, evaluate controls, analyze findings, and provide practical recommendations to improve security and risk posture. Develop detailed reports, executive presentations, and management summaries tailored to both technical and business audiences. Facilitate stakeholder workshops, interviews, and working sessions with technology, security, risk, and business teams. Manage multiple engagements, ensuring timely delivery, quality assurance, and adherence to leading practices. Mentor and coach junior team members, contributing to capability development and knowledge sharing across the practice. Stay updated on emerging cyber threats, technology trends, regulatory changes, and industry best practices
Skills and attributes for success
Strong understanding of cybersecurity governance, cybersecurity and technology risk management as well as risk assessment methodologies. Experience conducting technology, cybersecurity, and operational risk assessments. Knowledge of industry frameworks and standards such as ISO 27001, NIST CSF, NIST 800-53, CIS Controls, COBIT, and ITIL. Familiarity with cybersecurity regulations and regulatory compliance requirements across regional (MENA) and international jurisdictions. Experience developing and reviewing cybersecurity policies, procedures, standards, and governance documentation. Understanding of cyber resilience, business continuity, disaster recovery, and third-party risk management concepts. Ability to analyze complex technical and business issues and communicate findings clearly to stakeholders. Experience working within consulting environments and managing multiple stakeholder groups. Strong analytical, problem-solving, and critical-thinking skills. Excellent written, verbal, and presentation skills. Ability to work independently while collaborating effectively within multidisciplinary teams.
To qualify for the role, you must have
A bachelor's or master’s degree in information